← Blog

Double Counter Breach: 28M Discord Users’ IPs Exposed

Share on X

Double Counter — the Discord security bot that verifies members and flags alt accounts across hundreds of thousands of communities — confirmed a deliberate multi-stage intrusion on 4 October 2026. In incident report INC-2026-10-04, Tellter SAS (the French operator behind Double Counter and related products) describes how attackers broke into a retired OVH server still running a public self-hosted Metabase analytics instance, forged an administrator session, stole cloud credentials, and copied roughly 12 GB from one production database in about twenty-five minutes. The company treats as exposed approximately 28 million Discord user IDs and usernames, 27 million IP addresses with coarse geolocation, 25 million user-agent hashes, and about 1.0 million deduplicated email addresses. Primary source: Double Counter’s security incident report. Canonical BreachHistory record: https://breachhistory.com/double-counter/double-counter2026 (/double-counter/double-counter2026).

This is a verified Double Counter data breach — company attestation with a detailed forensic timeline, not an anonymous forum dump. Have I Been Pwned later loaded a public corpus of 274,922 unique emails paired with Discord usernames (a subset of the company’s million-email figure). Trade coverage from The Verge and others tracked the same disclosure. Discord told press it had disabled new installs of the bot while reviewing scope with the vendor.

What happened — Metabase on a retired OVH box

Double Counter’s job is friction on purpose. When a member verifies in a protected Discord server, the bot records identifiers that help moderators spot alts, VPN hopping, and raid patterns. That inventory — Discord IDs, usernames, IP addresses, ISP and city-level location, hashed user agents, and optional emails from Doogle and dashboard accounts — is exactly why a Double Counter Discord bot hack lands harder than a typical SaaS contact-list leak.

The entry point was not the live verification stack. It was an old OVH host from a previous hosting setup: no longer linked to the operational service, but still reachable from the internet with Metabase running. Attackers began probing from rotating VPN addresses on 3 October 2026 at 04:37 UTC, walked a username list (root, nathan, debian, analytics-sync, metabase, and similar), and logged in at 00:47 on 4 October. A vulnerability in the self-hosted Metabase instance let them forge an administrator session, reach the host, and recover two cloud credentials stored there: a service-account key with administrator rights and an administrator’s saved command-line session. The company stresses the credentials were not sitting in source code.

From there the intrusion moved into live cloud infrastructure. First use of the service-account key hit at 12:03 UTC. Within minutes the attacker added an SSH key, started a database export to a bucket they created (that export was never downloaded), opened a shell inside a running bot container, and read the Discord bot token. That token became a second weapon: messages that looked like Double Counter itself.

Timeline of the 4 October 2026 attack

All times below are UTC and follow Double Counter’s published log-backed timeline (approximate markers noted as in the company report).

  1. 3 October, 04:37 — First probing of the legacy OVH server and an internal API from rotating VPN addresses.
  2. 4 October, 00:47 — Login via the Metabase vulnerability after username enumeration.
  3. 12:03–12:35 — Service-account key used in cloud; SSH key added; database export to attacker bucket (never downloaded).
  4. 12:26 — Shell in a bot container; Discord bot token obtained.
  5. 13:24–13:34 — On Double Counter’s support server: attacker account granted Administrator and roughly fifteen roles; staff ban/unban fight; Discord ID 931487207443804161 named in the report.
  6. From ~13:30 — Compromised bot posts invitations to the attacker’s Discord server in about 50 large communities (largest named: “Steal a brainrot”).
  7. 13:39 — Company invalidates the bot token; bot goes offline.
  8. ~14:45–14:51 — New token installed; attacker reads the replacement within about two minutes and reopens container shells.
  9. 15:04–15:09 — Attacker deletes backups they created and changes the database administrator password, locking company services out.
  10. 15:09–15:34 — Roughly 12 GB of database tables copied from a cloud-hosted machine until the session is terminated.
  11. 15:17–15:36 — Intrusion spotted in cloud audit logs; service-account key disabled; SSH key removed; database closed to the internet; password rotated; stolen key deleted.
  12. 15:54–17:54 — Attacker falls back to the administrator CLI session from the same OVH box, re-adds SSH access, reconnects to the database with no measurable further transfer; last cloud action at 17:54:57.
  13. 17:11–17:14 — Stolen Stripe key on a separate Tellter product (Atis) used for fraudulent charges; all payment keys revoked and customer charges refunded.
  14. ~18:00 — Legacy OVH server shut down; backdoor audit of 14 cloud projects finds no persistence.
  15. ~18:35–18:40 — Invite spam via two Discord webhooks on the support server; ten exposed webhooks deleted.
  16. 19:19 — Double Counter restored with new credentials after secret rotations and session-signing key replacement.

Net: about 5 hours 51 minutes of attacker activity in the cloud (12:03 → 17:54), with service fully restored by 19:19 under continuous monitoring. The company says a full audit found no backdoor left behind.

What data was exposed — and what was not

Double Counter’s copy tool walks tables in a fixed order. By comparing the ~12 GB that left with table sizes, Tellter reconstructed what crossed the wire. Counts are approximate; where only a partial table left, the company treats the entire related population as exposed.

Treated as exposed

  • Discord user IDs and usernames — ≈ 28 million accounts (partly copied; treated as exposed).
  • IP addresses and coarse geolocation — ≈ 27 million accounts: country, region, city, postal code, and ISP. Alt-detection IPs (~5.4M) copied in full; verified-user IPs (~21.7M) were mid-copy when the session died — volume suggests ~20% left, so the whole set is treated as exposed.
  • User-agent hashes — ≈ 25 million accounts: one-way hashes of browser user agent plus city/country, used for alt detection.
  • Email addresses (deduplicated) — ≈ 1.0 million: roughly 840,000 Doogle accounts plus about 240,000 from the Double Counter dashboard, server-manager, customer, and advertiser contacts.

Not copied / not in scope of this dump

  • VPN detection logs — ≈ 15 million IP/user-agent rows not copied.
  • Behavioural fingerprint database — stored elsewhere; confirmed not accessed.
  • Cold storage — separate database covering ≈ 58 million users (only ~800k emails); outside the involved infrastructure and unaffected.
  • Full 5.0 GB export created at 12:35 to the attacker’s bucket — never downloaded.
  • Discord passwords — Double Counter never receives them.
  • Stored payment card numbers — held by the payment provider, not in the affected database.

For readers asking what a dump of Discord IP addresses actually enables: pairing a Discord ID with a home or mobile IP, ISP, and city turns “anonymous” community drama into real-world targeting. It also fuels highly convincing phishing — “we detected a new login from your city; re-verify with Double Counter” — especially when the email corpus sits alongside usernames.

Bot token abuse and phishing Discord verification

Stealing the bot token was not a side quest. From about 13:30 UTC the compromised Double Counter bot posted invitations to the attacker’s own Discord server inside roughly fifty large communities that trust the bot for verification. Those messages appeared as sent by Double Counter. Substantially all were later deleted by Tellter or by each server’s moderators. The company deliberately does not link the attacker’s invite.

That is the phishing Discord verification problem in the wild: users are trained to click whatever the security bot says. An invite that looks official, arriving mid-outage, is social engineering with a trusted avatar. Server admins were told to delete any Double Counter message between 12:00 and 16:30 UTC on 4 October that invited people to another server, and to review audit logs for bot actions in that window.

Members who verified between 13:39 and 14:49 UTC without receiving their role were told to verify again after the token reset. Members were also told they do not need to change Discord passwords because Double Counter never held them — but they should not join servers advertised in unexpected Double Counter messages.

Stolen Stripe key and payment fraud

Among secrets readable in the cloud was a Stripe key for a separate Tellter product, Atis — not the payment account that processes Double Counter and Doogle subscriptions. Between 17:11 and 17:12 UTC the attacker ran escalating test charges ($1, $10, $100, $1,000) against one company card, totaling $7,316, plus $3 and $15 on two customer cards. All three cards were the only ones charged; both customer charges were refunded in full; every payment-provider key was revoked at 17:14. The company states customer funds are safe and that no stored card numbers were exposed — the attacker acted through the Stripe account, not by dumping PAN data. The Double Counter / Doogle subscription payment account showed no unauthorized charges.

Who is at risk

Discord members who verified through Double Counter — especially anyone whose IP and username land in the ~27–28 million treated-as-exposed sets — should expect targeted DMs, fake re-verification pages, and doxxing attempts that cite a real ISP or city. Treat unsolicited “Double Counter” links as hostile until you confirm them inside a known-good client session.

Doogle users, advertisers, and API customers — the company says their emails were among the ~1.0 million copied. Expect phishing that references Doogle or Double Counter billing. Tellter says it never asks for passwords, tokens, or payment by email or private message.

Server administrators — review moderation logs for the 4 October window, purge attacker invites, and watch for follow-on accounts impersonating staff. Discord’s temporary block on new installs of the bot (reported by trade press quoting Discord) means communities that had not yet added Double Counter cannot onboard it until Discord and Tellter finish their review.

Atis customers — only two small fraudulent charges, both refunded; no broader card-data exposure asserted. Still watch statements for any later findings.

People only in cold storage (~58M) — the company says that corpus was not involved. That is a meaningful “not in this dump” claim, but it does not protect anyone who also appears in the live verification tables.

Have I Been Pwned Double Counter load

On 7 October 2026, Have I Been Pwned indexed a Double Counter breach entry. Troy Hunt’s summary attributes the incident to the Metabase path described in Tellter’s notice and states attackers gained access to a subset of data. The public corpus HIBP loaded contains 274,922 unique email addresses and Discord usernames — far smaller than the company’s ~1.0 million email figure, and explicitly a published subset rather than the full internal database copy. HIBP also notes a small number of paying-subscriber records with names, countries, and postcodes in that public set.

Practical takeaway: a clean HIBP check does not prove you were outside the 28 million Discord ID / 27 million IP exposure. HIBP can only match identities present in the emails it ingested. Discord-only accounts without an email in the public dump will not light up even if their IP and username left the production database.

Industry context — Discord bots as identity brokers

Discord has spent years pushing users toward bots that gate communities: Captcha alternatives, phone-less age checks, anti-raid tooling, and alt detection. Each of those products becomes a shadow identity layer sitting beside Discord’s own systems. Double Counter’s own marketing pitch — data-powered verification across a huge install base — is why tens of millions of Discord IP addresses existed in one place to begin with.

The architectural failure mode here is familiar to anyone who has chased cloud breaches: a retired server left public, an analytics tool with an admin-session forgery bug, and long-lived cloud credentials with administrator rights. The attackers did not need a zero-day against Discord. They needed one forgotten Metabase host and patience. When staff rotated the bot token, the attacker simply read the new secret from the same privileged foothold within two minutes — a reminder that secret rotation without removing the privilege path is incomplete containment.

Comparisons that matter for readers: Discord’s own past third-party vendor incidents (including government-ID image exposure reported for some users in prior years) already trained the community to worry about verification vendors. This Double Counter breach is different in scale and in the IP-address inventory, but it sits in the same category — trust placed in a community-security product that stores more PII than most members realize.

What the company and regulators said

Tellter published the incident report on 5 October 2026, apologized, and listed concrete containment: service-account deletion, administrator session revocation, OVH shutdown, database moved off the public internet, cache database migrated onto a private cloud network, bot token and webhooks moved into a dedicated secret store, logging of every secret read, and alerting on sensitive cloud changes. The firm notified the French data protection authority (CNIL) on 5 October under reference FR2610050000001, engaged counsel, and said it is pursuing those responsible in France and the United States with a criminal complaint in progress.

Discord, separately, told reporters that while this was not a breach of Discord itself, the platform had disabled new installs of the Double Counter app while working with the vendor on full scope. That platform action is the clearest signal that Discord treats third-party verification bots as systemic risk when their tokens and member databases burn.

Action items — what to do after the Double Counter breach

  1. Assume phishing. Any email, DM, or “Double Counter” message asking you to re-verify, pay a fine, or paste a token is hostile. Use only flows you start yourself inside Discord or on the official doublecounter.gg domain.
  2. Check HIBP for email hits at Have I Been Pwned’s Double Counter entry, then remember a miss does not clear IP/username exposure.
  3. Server admins: delete invite spam from Double Counter dated 4 October 12:00–16:30 UTC; audit bot permission grants; watch for staff impersonation.
  4. Doogle / dashboard / advertiser contacts: treat your email as burned for spear-phishing; enable MFA on every related account; watch billing portals for fake invoices.
  5. Atis customers: confirm the $3 / $15 refunds if you were one of the two charged cards; revoke and re-issue cards only if your bank advises it after reviewing statements.
  6. Do not rotate Discord passwords solely because of this bot — Double Counter never held them — but do enable Discord MFA if you have not, and review authorized apps/bots on large servers you moderate.
  7. Document harassment. If someone cites your city, ISP, or Discord ID in a threat, preserve screenshots for Discord Trust & Safety and local law enforcement; Tellter lists [email protected] and the bot’s /privacy command for personal-data requests.

Canonical record and sources

BreachHistory indexes this as a verified 2026 incident with company-confirmed counts and a technical write-up grounded in INC-2026-10-04. Full catalog entry: /double-counter/double-counter2026.

Bottom line: a forgotten Metabase path on a retired OVH server became a forged admin session, cloud administrator credentials, a stolen Discord bot token, ~12 GB of verification data, and a short Stripe fraud spree — exposing Discord IP addresses and identifiers at a scale that turns community moderation tooling into a national-class privacy event for roughly twenty-eight million accounts.